Inspirational journeys

Follow the stories of academics and their research expeditions

CISM—Certified Information Security Manager - Part 106

Mary Smith

Tue, 21 Apr 2026

CISM—Certified Information Security Manager - Part 106

1. In a large organization, defining recovery time objectives (RTOs) is PRIMARILY the responsibility of:

A) the IT manager.
B) the information security manager.
C) the business unit manager.
D) senior manager.



2. Which metric is the BEST indicator that an update to an organization's information security awareness strategy is effective?

A) A decrease in the number of incidents reported by staff
B) A decrease in the number of email viruses detected
C) An increase in the number of email viruses detected
D) An increase in the number of incidents reported by staff



3. An organization involved in e-commerce activities operating from its home country opened a new office in another country with stringent security laws. In this scenario, the overall security strategy should be based on:

A) risk assessment results.
B) international security standards.
C) the most stringent requirements.
D) the security organization structure.



4. Which of the following is the PRIMARY reason to conduct periodic business impact assessments?

A) Improve the results of last business impact assessment
B) Update recovery objectives based on new risks
C) Decrease the recovery times
D) Meet the needs of the business continuity policy



5. Which of the following is the BEST approach to make strategic information security decisions?

A) Establish an information security steering committee.
B) Establish periodic senior management meetings.
C) Establish regular information security status reporting.
D) Establish business unit security working groups.



1. Right Answer: D
Explanation:

2. Right Answer: A
Explanation:

3. Right Answer: D
Explanation:

4. Right Answer: B
Explanation:

5. Right Answer: D
Explanation:

0 Comments

Leave a comment